Establishing a secure communication link
Summary by NHIP
Secure Link Establishment
The device uses dual-protocol circuitry to establish a secure wireless connection. Upon receiving a first signal, it transmits advertisements and random data at a first power magnitude lower than a second power magnitude, sending an encrypted first encryption key to external devices.
Claim Score by NHIP
Abstract
This disclosure is directed to devices, systems, and techniques for establishing a secure connection between two or more devices. In some examples, a device is configured for wireless communication. The device comprises signal reception circuitry configured to receive communications transmitted according to at least a first communication protocol, communication circuitry configured for wireless communication according to at least a second communication protocol, and processing circuitry electrically coupled to the signal reception circuitry and the communication circuitry. The processing circuitry is configured to receive, via the signal reception circuitry, a first signal according to the first communication protocol. In response to receiving the first signal, the processing circuitry is further configured to transmit, via the communication circuitry, a second signal according to the second communication protocol and establish a secure link according to the second communication protocol.

Term
13.7 yearsleft in the term
Expires 6 June 2040, including 492 days of term adjustment.
- Priority and filed
- Granted
- Today
- Expires
26 claims: 3 independent, 23 dependent
- 1A device configured for wireless communication, wherein the device comprises:signal reception circuitry configured to receive communications transmitted according to at least a first communication protocol;communication circuitry configured to send communications and receive communications according to at least a second communication protocol different than the first communication protocol;and processing circuitry electrically coupled to the signal reception circuitry and the communication circuitry, wherein the processing circuitry is configured to: receive, from one or more external devices via the signal reception circuitry, a first signal according to the first communication protocol;in response to receiving the first signal, transmit, via the communication circuitry, a second signal including a set of advertisements according to the second communication protocol;in response to transmitting the second signal including the set of advertisements, receive, from the one or more external devices, a first set of random data according to the second communication protocol;generate a second set of random data;transmit the second set of random data, a challenge, and a first encryption key to the one or more external devices according to the second communication protocol at a first power magnitude, wherein the first power magnitude is less than a second power magnitude, wherein the first encryption key is encrypted, and wherein the challenge is not encrypted;calculate, based on the first set of random data, the second set of random data, and the first encryption key, a second encryption key;receive, from the one or more external devices, the challenge according to the second communication protocol, wherein the challenge is encrypted;decrypt the challenge using the second encryption key;verify the challenge by comparing the decrypted challenge with the transmitted challenge;and transmit, to the one or more external devices according to the second communication protocol, a verification signal which confirms that the challenge is verified and establishes a secure link between the device and the one or more external devices according to the second communication protocol, and wherein communications transmitted over the established secure link are according to the second communication protocol at the second power magnitude.
- 17Broadest claimClaim Score 21, narrow(NHIP)A method comprising:receiving, by signal reception circuitry of a device configured to receive communications transmitted according to at least a first communication protocol, a first signal from one or more external devices according to the first communication protocol;in response to receiving the first signal, transmitting, via communication circuitry configured to send communications and receive communications according to at least a second communication protocol different from the first communication protocol, a second signal including a set of advertisements according to the second communication protocol;in response to transmitting the second signal including the set of advertisements, receiving, by processing circuitry electrically coupled to the signal reception circuitry and the communication circuitry, a first set of random data from the one or more external devices according to the second communication protocol;generating, by the processing circuitry, a second set of random data;transmitting, by the processing circuitry, the second set of random data, a challenge, and a first encryption key to the one or more external devices according to the second communication protocol at a first power magnitude, wherein the first power magnitude is less than a second power magnitude, wherein the first encryption key is encrypted, and wherein the challenge is not encrypted;calculating, by the processing circuitry based on the first set of random data, the second set of random data, and the first encryption key, a second encryption key;receiving, by the processing circuitry from the one or more external devices, the challenge according to the second communication protocol, wherein the challenge is encrypted;decrypting, by the processing circuitry, the challenge using the second encryption key;verifying, by the processing circuitry, the challenge by comparing the decrypted challenge with the transmitted challenge;and transmitting, by the processing circuitry to the one or more external devices according to the second communication protocol, a verification signal which confirms that the challenge is verified and establishes a secure link between the device and the one or more external devices according to the second communication protocol, wherein communications transmitted over the established secure link are according to the second communication protocol at the second power magnitude.
- 26A system comprising:a first device comprising: signal reception circuitry configured to receive communications transmitted according to at least a first communication protocol;first communication circuitry configured to send communications and receive communications according to at least a second communication protocol different from the first communication protocol;and first processing circuitry electrically coupled to the signal reception circuitry and the first communication circuitry, wherein the first processing circuitry is configured to: receive, from one or more external devices via the signal reception circuitry, a first signal according to the first communication protocol;and in response to receiving the first signal, transmit, via the first communication circuitry, a second signal including a set of advertisements according to the second communication protocol;in response to transmitting the second signal including the set of advertisements, receive, from the one or more external devices, a first set of random data according to the second communication protocol;generate a second set of random data;transmit the second set of random data, a challenge, and a first encryption key to the one or more external devices according to the second communication protocol at a first power magnitude, wherein the first power magnitude is less than a second power magnitude, wherein the first encryption key is encrypted, and wherein the challenge is not encrypted;calculate, based on the first set of random data, the second set of random data, and the first encryption key, a second encryption key;receive, from the one or more external devices, the challenge according to the second communication protocol, wherein the challenge is encrypted;decrypt the challenge using the second encryption key;verify the challenge by comparing the decrypted challenge with the transmitted challenge;and transmit, to the one or more external devices according to the second communication protocol, a verification signal which confirms that the challenge is verified and establishes a secure link between the device and the one or more external devices according to the second communication protocol;and a second device comprising: second communication circuitry configured to send communications according to the first communication protocol having a first range and the second communication protocol having a second range, the second communication protocol different than the first communication protocol and the second range greater than the first range;and second processing circuitry electrically coupled to the second communication circuitry, wherein the one or more external devices comprise the second device, and wherein the second processing circuitry is configured to: transmit, via the second communication circuitry, the first signal to the first device according to the first communication protocol;in response to transmitting the first signal, receive, via the second communication circuitry and from the first device, the second signal according to the second communication protocol;generate a first set of random data;transmit, to the first device, via the second communication circuitry, the first set of random data according to the second communication protocol;receive the second set of random data, the challenge, and the first encryption key from the first device according to the second communication protocol at the first power magnitude;decrypt the first encryption key;calculate the second encryption key based on the first set of random data, the second set of random data, and the decrypted first encryption key;encrypt the challenge based on the second encryption key;transmit the challenge to the first device;and in response to transmitting the challenge, receive the verification signal which confirms that the challenge is verified and establishes a secure link according to the second communication protocol, and wherein communications transmitted over the established secure link are according to the second communication protocol at the second power magnitude.
Independent claims3
114 paragraphs in 5 sections, as filed
TECHNICAL FIELD
0001The disclosure relates to device communication and, more particularly, establishing secure communication links between two or more devices.
BACKGROUND
0002A computing device may be configured to transmit communications to, and receive communications from, other computing devices. These communications may include data or any information that is transmitted between devices either wirelessly or via a wired connection. Communications that are public or otherwise do not include sensitive information may be unsecured. Communications that are intended to be private to two or more devices may be encrypted such that the information contained therein is not readily available to unauthorized devices. For example, an implantable medical device (IMD) may exchange sensitive information with one or more external devices via an encrypted wireless communication link. However, communication environments outside of the medical device space may also be used to exchange sensitive information.
0003IMDs may be surgically implanted in a patient to monitor one or more physiological parameters of the patient and/or deliver therapy to suppress one or more symptoms of the patient. For example, an IMD may include a cardiac monitor, be configured to deliver cardiac pacing or another electrical therapy to the patient, and/or be configured to terminate tachyarrhythmia by delivery of high energy shocks. A clinician or patient may use an external device to retrieve information collected by the IMD and/or to configure or adjust one or more parameters of the monitoring and/or therapy provided by the IMD. Typically, the external device connects to the IMD via a wireless connection. In some examples, a wireless connection is established between the external device and the IMD using a Bluetooth® wireless protocol. In such an example, the external device is treated as a central device, and one or more IMDs are treated as peripheral devices.
0004In some examples, communications between an external device (e.g., a medical device programmer or data acquisition device) and an IMD (e.g., a pacemaker, a defibrillator, a neurostimulator, a cardiac monitor, or a drug pump, as examples) may be encrypted to secure sensitive information such as collected patient data or programming instructions that at least partially define the operation of an IMD. Secure communication involving medical devices may involve an encryption scheme known to both the external device and the IMD. For example, both the external device and the IMD may utilize a stored encryption key to encrypt and/or decrypt some or all information transmitted between the devices.
SUMMARY
0005In general, the disclosure is directed to devices, systems, and techniques for establishing a secure connection between two or more devices. For example, this disclosure describes techniques for using an external device to establish a secure connection between an IMD, the external device, and, in some cases, an additional external device. Prior to secure communication according to a second communication protocol, the external device may initiate a pairing procedure by emitting a signal according to a first communication protocol. While the first communication protocol is, in some examples, unknown to the IMD, the IMD is configured to sense the first signal based on electric field variations caused by the signal. During the pairing procedure, the devices may each generate at least one encryption key (e.g., session key) based on random numbers generated by the devices. The IMD may send a challenge to the external device, and based on a verification of the challenge, the devices may establish a secure link. Following the pairing procedure, the devices may securely communicate using the session keys until the secure link is terminated. For instance, the external device, or the additional external device, may be a programming device configured to communicate with the IMD to modify one or more settings of the IMD and receive patient data from the IMD.
0006In some examples, the communication range of the second protocol is greater than that of the first protocol. During the pairing procedure, however, communication with the IMD may be according to a reduced power mode and, consequently, reduced range implementation of the second protocol, in some cases. In some examples, subsequent to pairing, the power and communication range will no longer be reduced for secured communication with the IMD according to the second protocol. In some examples, the signal according to the first protocol is a wake-up signal for the IMD, e.g., transitions at least some circuitry, such as communication circuitry, of the IMD from a relatively lower energy consumption mode into a relatively higher energy consumption mode in which communication with one or more external devices occurs. In one example, the IMD transitions its communication circuitry from being in an off state in which the communication circuitry is not transmitting or receiving to being in an on state during which the communication circuitry is capable of transmitting and receiving. In another example, the IMD transitions from a first relatively lower energy consumption mode in which advertisement signals are transmitted at a first rate to a second relatively higher energy consumption mode in which advertisement signals are transmitted at a second, faster rate which results in increased power consumption.
0007The techniques of this disclosure may provide one or more advantages. For example, before the establishment of a secure link between a first device and a second device, the second device may not have access to an encryption key for encoding or decoding data exchanged with the first device. An example second device of this disclosure may initiate the generation of an encryption key which enables the second device to communicate securely with first device. The second device may send a relatively close-range signal to the first device, starting a process which generates the encryption key. By using the close-range signal, the second device decreases a probability that the signal may be fraudulently replicated by a third-party device. After the generation of the encryption key, the first device and the second device may exchange information at a relatively longer range than the close-range signal initially sent from the second device to the first device. Additionally, in some examples, the first device is configured to communicate exclusively using a particular protocol, such as a Bluetooth® protocol. At least some techniques of this disclosure allow the first device to receive and identify signals that are not transmitted using the Bluetooth® protocol, enabling the second device to initiate the pairing process using a custom, non-Bluetooth® signal that is not easily replicated by any device with Bluetooth® capabilities.
0008In some examples, a first device is configured for wireless communication. The first device includes signal reception circuitry configured to receive communications transmitted according to at least a first communication protocol, communication circuitry configured for wireless communication according to at least a second communication protocol, and processing circuitry electrically coupled to the signal reception circuitry and the communication circuitry. The processing circuitry is configured to receive, via the signal reception circuitry, a first signal according to the first communication protocol. In response to receiving the first signal, the processing circuitry is further configured to transmit, via the communication circuitry, a second signal according to the second communication protocol and establish a secure link according to the second communication protocol, where to establish the secure link, the processing circuitry is configured to transmit at least one signal at a first power magnitude, and where communications transmitted over the secure link are at a second power magnitude greater than the first power magnitude.
0009In other examples, a method includes receiving, by signal reception circuitry of a first device configured to receive communications transmitted according to at least a first communication protocol, a first signal according to the first communication protocol. In response to receiving the first signal, the method further includes transmitting, via communication circuitry, a second signal according to a second communication protocol and establishing a secure link according to the second communication protocol, where establishing the secure link comprises transmitting at least one signal at a first power magnitude, and where communications transmitted over the secure link are at a second power magnitude greater than the first power magnitude.
0010In other examples, a system includes a first device including signal reception circuitry configured to receive communications transmitted according to at least a first communication protocol, communication circuitry configured for wireless communication according to at least a second communication protocol, and first processing circuitry electrically coupled to the signal reception circuitry and the communication circuitry. The first processing circuitry is configured to receive, via the signal reception circuitry, a first signal according to the first communication protocol. In response to receiving the first signal, the first processing circuitry is further configured to transmit, via the communication circuitry, a second signal according to the second communication protocol. The system further includes a second device including second communication circuitry configured for wireless communication according to the first communication protocol having a first range and the second communication protocol having a second range, the second communication protocol different than the first communication protocol and the second range greater than the first range, and second processing circuitry electrically coupled to the second communication circuitry. The second processing circuitry is configured to transmit, via the second communication circuitry, the first signal to the first device according to the first communication protocol. In response to transmitting the first signal, the second processing circuitry is further configured to receive, via the second communication circuitry and from the first device, the second signal according to the second communication protocol. In response to receiving the second signal, the second processing circuitry is further configured to establish a secure link according to the second communication protocol, wherein the secure link includes the first device and at least one of the second device and a third device, where to establish the secure link, the second processing circuitry is configured to receive at least one signal at a first power magnitude, and where communications transmitted over the secure link are at a second power magnitude greater than the first power magnitude.
0011The summary is intended to provide an overview of the subject matter described in this disclosure. It is not intended to provide an exclusive or exhaustive explanation of the systems, device, and methods described in detail within the accompanying drawings and description below. Further details of one or more examples of this disclosure are set forth in the accompanying drawings and in the description below. Other features, objects, and advantages will be apparent from the description and drawings, and from the claims.
BRIEF DESCRIPTION OF DRAWINGS
0012<figref idref="DRAWINGS">FIG. <b>1</b></figref> illustrates the environment of an example medical device system in conjunction with a patient and a heart of the patient, in accordance with one or more techniques of this disclosure.
0013<figref idref="DRAWINGS">FIG. <b>2</b></figref> is a block diagram illustrating an example configuration of components of an implantable medical device (IMD), in accordance with one or more techniques of this disclosure.
0014<figref idref="DRAWINGS">FIG. <b>3</b></figref> is a block diagram illustrating an example configuration of components of an example external device, in accordance with one or more techniques of this disclosure.
0015<figref idref="DRAWINGS">FIG. <b>4</b></figref> is a block diagram illustrating an example configuration of components of another example external device, in accordance with one or more techniques of this disclosure.
0016<figref idref="DRAWINGS">FIG. <b>5</b></figref> is a flow diagram illustrating an example operation in accordance with one or more techniques of this disclosure.
0017Like reference characters denote like elements throughout the description and figures.
DETAILED DESCRIPTION
0018This disclosure describes techniques for establishing a secure connection between two or more devices. In some examples, a secure link is established between at least one implantable medical device (IMD) and at least one external device. An external device may be used to, for example, transmit a signal to the IMD in order to initiate an encryption key generation process which would enable at least one external device to exchange encrypted data with the IMD. However, the techniques of this disclosure are not limited to implantable devices or medical devices. The techniques may be used to establish a secure link between any two or more devices that can communicate with each other.
0019In some examples, an IMD records one or more physiological signals of a patient, where the one or more physiological signals may be indicative of a medical condition. The IMD may use any combination of electrodes, chemical sensors, temperature sensors, or other sensors to sense the physiological signals and store data indicative of the physiological signals in a memory. In some examples, the IMD delivers therapy, such as cardiac pacing or anti-tachyarrhythmia shocks, and store data indicative of the therapy delivered. In some examples, the IMD stores data regarding the status and performance of the IMD and components thereof, and operational parameters that control the functioning of the IMD, e.g., for sensing and/or delivering therapy.
0020Since the IMD is implanted within the patient, in some cases, the IMD may wirelessly communicate with an external device, e.g., to transmit at least some of the data to an external device for analysis by a clinician. Additionally, a user (e.g., the patient or the clinician) may provide user input to an external device to control the IMD. The external device may in turn transmit instructions to the IMD based on the user input. Since information exchanged between the IMD and the external device may be sensitive and is communicated wirelessly, it may be beneficial to exchange data with the IMD using a secure link such as an encrypted link.
0021To transfer data using an encrypted link, a plurality of different encryption algorithms may be used. Such algorithms may include Rivest-Shamir-Adleman (RSA), advanced encryption standard (AES), elliptic curve integrated encryption scheme (ECIES), data encryption standard (DES), twofish, threefish, or key exchange method, as examples. While different encryption algorithms vary in their methods of encoding and decoding data, most encryption algorithms rely on encryption keys for the encoding and the decoding process. For example, a first device may encode a message using a first encryption key and transmit the encoded message to a second device. The second device may decode the message using a second encryption key, where the second encryption key corresponds to the first encryption key. Consequently, if the external device does not possess an encryption key corresponding to an encryption key of the IMD, then the external device may be unable to securely communicate with the IMD.
0022The external device is configured to initiate a process to generate a set of encryption keys (e.g., “session” keys) which allow one or more external devices to communicate with the implantable medical device. The external device may send an initial signal to the IMD to begin the process of creating the set of encryption keys. The initial signal may also, in some cases, “wake up” the IMD for a communication session (e.g., cause the IMD to supply a greater amount of power to communication circuitry of the IMD). The initial signal may have a short transmission range (e.g., less than about 20 centimeters (cm)), decreasing a probability that a fraudulent device would be able to imitate the initial signal to start the key creation process. In some cases, the external device or a portion thereof used to facilitate communication with the IMD must be placed directly across the patient's skin from the IMD for the initial signal transmission to be successful. After the IMD receives the initial signal, the external device and the IMD may generate the set of encryption keys and establish the secure link.
0023<figref idref="DRAWINGS">FIG. <b>1</b></figref> illustrates the environment of an example medical device system <b>2</b> in conjunction with a patient <b>4</b> and a heart <b>6</b> of patient <b>4</b>, in accordance with one or more techniques of this disclosure. The example techniques may be used with an IMD <b>16</b>, which may be in wireless communication with at least one of external device <b>18</b> and external device <b>20</b>. In some examples, IMD <b>16</b> is implanted outside of a thoracic cavity of patient <b>4</b> (e.g., subcutaneously in the pectoral location illustrated in <figref idref="DRAWINGS">FIG. <b>1</b></figref>). IMD <b>16</b> may be positioned near the sternum near or just below the level of heart <b>6</b>, e.g., at least partially within the cardiac silhouette. In some examples, IMD <b>16</b> takes the form of a LINQ™ Insertable Cardiac Monitor (ICM), available from Medtronic plc, of Dublin, Ireland.
0024Clinicians sometimes diagnose patients with cardiac conditions based on one or more observed physiological signals collected by physiological sensors, such as electrocardiogram (ECG) electrodes, electrogram (EGM) electrodes, chemical sensors, or temperature sensors. In some cases, clinicians apply non-invasive sensors to patients in order to sense one or more physiological signals while a patent is in a clinic for a medical appointment. However, in some examples, physiological markers (e.g., irregular heartbeats) of a cardiac condition are rare. As such, in these examples, a clinician may be unable to observe the physiological markers needed to diagnose a patient with a heart condition while monitoring one or more physiological signals of the patient during a medical appointment. In the example illustrated in <figref idref="DRAWINGS">FIG. <b>1</b></figref>, IMD <b>16</b> is implanted within patient <b>4</b> to continuously record one or more physiological signals of patient <b>4</b> over an extended period of time.
0025In some examples, IMD <b>16</b> includes a plurality of electrodes. The plurality of electrodes are configured to detect signals that enable processing circuitry of IMD <b>16</b> to determine current values of additional parameters associated with the cardiac and/or lung functions of patient <b>4</b>. In some examples, the plurality of electrodes of IMD <b>16</b> are configured to detect a signal indicative of an electric potential of the tissue surrounding the IMD <b>16</b>. Moreover, IMD <b>16</b> may additionally or alternatively include one or more accelerometers, temperature sensors, chemical sensors, light sensors, pressure sensors, in some examples. Such sensors may detect one or more physiological parameters indicative of a patient condition.
0026External device <b>18</b> may include a housing which encloses processing circuitry electrically coupled to communication circuitry, a memory, and a user interface. In some examples, external device <b>18</b> is physically separate from external device <b>20</b>. The user interface of external device <b>18</b> may include, for example, at least one button. Additionally, or alternatively, the user interface of external device <b>18</b> may include any other device, sensor, or medium configured for accepting user input. In some examples, the user interface of external device <b>18</b> enables a user to initiate one or more techniques of this disclosure which establish a secure (e.g., encrypted) link with IMD <b>16</b> for a period of time. Although external device <b>18</b> may be physically separated from external device <b>20</b>, external device <b>18</b> is configured to, for example, establish a secure connection between external device <b>20</b> and IMD <b>16</b>. In some cases, external device <b>18</b> may act as an intermediary for communication between external device <b>20</b> and IMD <b>16</b>, e.g., during a secure communication session. In other cases, external device <b>18</b> may establish a secure link with IMD <b>16</b> without including any additional devices (e.g., external device <b>20</b>).
0027In some examples, external device <b>18</b> is configured for handheld use. In fact, a user may, in some cases, be able to fit external device <b>18</b> in the palm of a single hand while interacting with the user interface using at least one finger. In addition to being configured for handheld use, external device <b>18</b> may be configured to transmit signals via the communication circuitry according to at least one communication protocol. One communication protocol, for example, may enable external device <b>18</b> to send signals to IMD <b>16</b> over a short range (e.g., less than about 20 cm). For example, external device <b>18</b> may communicate via near-field communication technologies (e.g., inductive coupling, Near-field Communication (NFC) or other communication technologies operable at ranges less than 10-20 cm). Another example communication protocol may enable IMD <b>16</b>, external device <b>18</b>, and external device <b>20</b> to communicate over a relatively longer range. For example, external device <b>18</b> may communicate using far-field communication technologies (e.g., radiofrequency (RF) telemetry according to the 802.11 or Bluetooth® specification sets, or other communication technologies operable at ranges greater than near-field communication technologies).
0028External device <b>20</b> is configured to wirelessly communicate with IMD <b>16</b> as needed to provide or retrieve information. In some examples, external device <b>20</b> acts as an external programming device, e.g., medical device programmer, for IMD <b>16</b>. External device <b>20</b> is an external computing device that a user, e.g., the clinician and/or patient <b>4</b>, may use to communicate with IMD <b>16</b>. For example, external device <b>20</b> may be a clinician programmer that the clinician uses to communicate with IMD <b>16</b> and update one or more settings of IMD <b>16</b>. Additionally, or alternatively, external device <b>20</b> may be a patient programmer that allows patient <b>4</b> to control certain operations of IMD <b>16</b> and/or view and modify one or more operational parameter values of IMD <b>16</b>. The clinician programmer may include more programming features than the patient programmer. In other words, more complex or sensitive tasks may only be allowed by the clinician programmer to prevent an untrained patient from making undesired changes to IMD <b>16</b>.
0029External device <b>20</b> may be a hand-held computing device with a display viewable by the user and an interface for providing input to external device <b>20</b> (i.e., a user input mechanism). For example, external device <b>20</b> may include a small display screen (e.g., a liquid crystal display (LCD) or a light emitting diode (LED) display) that presents information to the user. In addition, external device <b>20</b> may include a touch screen display, keypad, buttons, a peripheral pointing device, voice activation, or another input mechanism that allows the user to navigate through the user interface of external device <b>20</b> and provide input. If external device <b>20</b> includes buttons and a keypad, the buttons may be dedicated to performing a certain function, e.g., a power button, the buttons and the keypad may be soft keys that change in function depending upon the section of the user interface currently viewed by the user, or any combination thereof.
0030In other examples, external device <b>20</b> may be a larger workstation or a separate application within another multi-function device, rather than a dedicated computing device. For example, the multi-function device may be a notebook computer, tablet computer, workstation, one or more servers, cellular phone, personal digital assistant, or another computing device that may run an application that enables the computing device to operate as a secure device. In some examples, a wireless adapter coupled to the computing device enables external device <b>18</b> to establish a secure link between the computing device and IMD <b>16</b>.
0031When external device <b>20</b> is configured for use by the clinician, external device <b>20</b> may be used to transmit instructions to IMD <b>16</b>. Example instructions may include requests to set electrode combinations for sensing and any other information that may be useful for programming into IMD <b>16</b>. The clinician may also configure and store operational parameters for IMD <b>16</b> within IMD <b>16</b> with the aid of external device <b>20</b>. In some examples, external device <b>20</b> assists the clinician in the configuration of IMD <b>16</b> by providing a system for identifying potentially beneficial operational parameter values.
0032Whether external device <b>20</b> is configured for clinician or patient use, external device <b>20</b> is configured to communicate with IMD <b>16</b> and, optionally, another computing device (e.g., external device <b>18</b>), via wireless communication. External device <b>20</b>, for example, may communicate via near-field communication technologies (e.g., inductive coupling, NFC or other communication technologies operable at ranges less than 10-20 cm) and far-field communication technologies (e.g., RF telemetry according to the 802.11 or Bluetooth® specification sets, or other communication technologies operable at ranges greater than near-field communication technologies).
0033In general, IMD <b>16</b>, external device <b>18</b>, and external device <b>20</b> may exchange information using at least one communication protocol. Communication protocols define sets of rules that define one or more aspects of data exchange between two or more entities of a network. In some examples, communication protocols are stored as lists of computer-readable instructions and communication protocols may be executed by any combination of hardware (e.g., physical circuitry) and software. An organization, such as a medical device manufacturer, may create its own communication protocols, license communication protocols from a third party, use open source communication protocols, or perform any combination thereof. In some examples, a communication protocol includes security provisions, such as password requirements and data encryption in order to secure the transfer of data between two or more devices in a network.
0034IMD <b>16</b> collects sensitive physiological data from patient <b>4</b>. Additionally, IMD <b>16</b> may receive data indicative of instructions from external device <b>20</b>, where the instructions cause IMD <b>16</b> to, as examples, update one or more settings, change one or more parameters, output data, or delete data. Consequently, communications (e.g., information or data) transmitted between external device <b>20</b> and IMD <b>16</b> may be encrypted to secure the communications from unauthenticated users and prevent external device <b>20</b> and IMD <b>16</b> from becoming compromised. For instance, communications transmitted between external device <b>20</b> and IMD <b>16</b> using a far-field communication protocol may be encrypted using a link key that is generated based on public encryption keys of external device <b>20</b> and IMD <b>16</b>. An encryption key may define a string of characters that is used to transform data into an encrypted form, decode encrypted data, or any combination thereof. As such, a first device may be unable to securely communicate with a second device if any one of the first device and the second device does not possess a respective encryption key associated with a secure link between the first device and the second device.
0035In some cases, external device <b>20</b> does not have access to a public encryption key associated with IMD <b>16</b> and is thus unable to transmit encrypted data to IMD <b>16</b>. In these cases, techniques for establishing a secure link between external device <b>20</b> and IMD <b>16</b> may be beneficial. In some example techniques of this disclosure, external device <b>18</b> is configured to establish the secure link by, in part, transmitting a short-range signal to IMD <b>16</b>.
0036Any combination of IMD <b>16</b>, external device <b>18</b>, and external device <b>20</b> may exchange information and data with each other. As illustrated in <figref idref="DRAWINGS">FIG. <b>1</b></figref>, IMD <b>16</b> is configured to communicate with external device <b>18</b> over communication link <b>22</b>, External device <b>18</b> is configured to communicate with external device <b>20</b> over communication link <b>24</b>, and IMD <b>16</b> is configured to communicate with external device <b>20</b> over communication link <b>26</b>. In some examples, each of communication links <b>22</b>, <b>24</b>, and <b>26</b> include any combination of secure channels (e.g., encrypted channels) and insecure channels (non-encrypted channels). Put another way, each of communication links <b>22</b>, <b>24</b>, and <b>26</b> represent all communications between the respective pairs of devices.
0037In one example, external device <b>18</b> is configured to transmit non-encrypted data to IMD <b>16</b> over communication link <b>22</b> and external device <b>18</b> is further configured to transmit encrypted data to IMD <b>16</b> over communication link <b>22</b>. In some examples, the communication circuitry of external device <b>18</b> is configured for wireless communication according to a first protocol and a second protocol, where the first protocol is different from the second protocol. For example, the first protocol defines a first range and the second protocol defines a second range. In other words, a maximum distance in which a signal may be transmitted according to the first protocol is different from a maximum distance in which a signal may be transmitted according to the second protocol. In some examples, the second range is greater than the first range. However, in other examples, the second range is less than or equal to the first range.
0038The processing circuitry of external device <b>18</b> may transmit, via the communication circuitry, a first signal to IMD <b>16</b> according to the first protocol. In some examples, the first protocol includes any communication protocol which uses magnetic induction communication, RF communication, or tissue conductance communication (TCC) via tissue of the patient. In some examples, the first range (e.g., the maximum range of the first signal) is less than about 20 cm. In other examples, the first range is less than about 10 cm.
0039In some examples, the first signal is defined by an electromagnetic waveform which acts as a “wake-up” signal for IMD <b>16</b>. Signal reception circuitry (not illustrated in <figref idref="DRAWINGS">FIG. <b>1</b></figref>) of IMD <b>16</b> may receive the first signal. The signal reception circuitry may be configured for sensing electromagnetic waveforms. After receiving the first signal, the signal reception circuitry may send data indicative of the first signal to the processing circuitry of <figref idref="DRAWINGS">FIG. <b>1</b></figref>. The first signal may, in some cases, cause the processing circuitry of IMD <b>16</b> to transition at least some circuitry, such as communication circuitry of IMD <b>16</b>, from a relatively lower energy consumption mode into a relatively higher energy consumption mode in which communication with one or more external devices occurs. Since IMD <b>16</b> is powered by a power source which, in some examples, has a limited lifespan, it may be beneficial to power the communication circuitry only when necessary for the functioning of IMD <b>16</b>. As such, IMD <b>16</b> may use the communication circuitry only after receiving the “wake up” signal, such as the first signal transmitted by external device <b>18</b>. For example, IMD <b>16</b> may transition the communication circuitry from being in an off state in which the communication circuitry is not transmitting or receiving to being in an on state during which the communication circuitry is capable of transmitting and receiving. The signal reception circuitry of IMD <b>16</b> may, in some cases, be separate from the communication circuitry of IMD <b>16</b>. In other cases, the signal reception circuitry may be a component of, or a part of the communication circuitry of IMD <b>16</b>. In either case, the signal reception circuitry is configured to sense the first signal which is transmitted from external device <b>18</b> to IMD <b>16</b>. In some examples, the signal reception circuitry may be configured for detecting TCC signals, where the first signal includes a TCC signal.
0040In some examples, the communication circuitry of IMD <b>16</b> periodically emits a sequence of advertisements according to the second protocol. Advertisements emitted by IMD <b>16</b> may broadcast to other devices the proximity and/or readiness of IMD <b>16</b> to communicate. IMD <b>16</b> may emit advertisements at a first advertisement rate prior to receiving the “wake up” signal and transition to a second, faster advertisement rate after receiving the “wake up” signal. In one example, the first advertisement rate may be greater than twenty advertisements per hour and less than sixty advertisements per hour. Put another way, consecutive advertisements of the sequence of advertisements may be separated by a period of time lasting greater than or equal to one minute and less than or equal to three minutes. In some examples, the first advertisement rate may be insufficient for establishing a secure link with another device (e.g., external devices <b>18</b>, <b>20</b>) in a desired amount of time. In response to detecting the first signal, IMD <b>16</b> increases the rate at which the communication circuitry of IMD <b>16</b> transmits advertisements to a second rate. The increased second advertisement rate increases the power consumption of IMD <b>16</b>, e.g., of the communication circuitry of IMD <b>16</b>. The second advertisement rate may be high enough to enable IMD <b>16</b> to establish a secure link with external devices <b>18</b>, <b>20</b> within a desired amount of time, e.g., seconds instead of minutes. In some examples, the second advertisement rate is greater than one advertisement per second. As such, the second advertisement rate is significantly higher than the first advertisement rate, and the communication circuitry of IMD <b>16</b> consumes more power when operating at the second advertisement rate than when the communication circuitry is operating at the first advertisement rate. In some examples, after receiving the first signal, IMD <b>16</b> operates at the second advertisement rate for a period of time, e.g., lasting up to thirty seconds, so as to not operate in the increased higher power consumption mode for too long. Since, in some cases, IMD <b>16</b> increases the advertisement rate from the first advertisement rate to the second advertisement rate only after receiving the first signal, IMD <b>16</b> may decrease a total amount of power required for establishing a secure link between IMD <b>16</b> and external devices <b>18</b>, <b>20</b>. This may increase a life span of the power source which provides power to the components of IMD <b>16</b>.
0041The processing circuitry of external device <b>18</b> may be configured to cause external device <b>18</b> to generate the first signal. In one example, the first signal includes a plurality of primary portions defining a first frequency value and a first duration. Additionally, the first signal includes a plurality of secondary portions defining a second frequency value and a second duration. The plurality of primary portions and the plurality of secondary portions are interleaved such that one primary portion occurs between two consecutive secondary portions and one secondary portion occurs between two consecutive primary portions.
0042In some examples, external device <b>18</b> is configured to transmit the first signal in response to a user input to the user interface of external device <b>18</b> (e.g., a press of the button). Alternatively, external device <b>18</b> may be configured to transmit the first signal in response to receiving data indicative of an instruction from external device <b>20</b>. In some examples, external device <b>18</b> transmits the first signal for a fixed amount of time lasting about 255 milliseconds (ms). Alternatively, in other examples, external device <b>18</b> transmits the first signal for a fixed amount of time lasting greater than or less than about 255 milliseconds. In other examples, external device <b>18</b> is configured to transmit the first signal for a period of time lasting as long as a user is pressing the button defining the user interface.
0043IMD <b>16</b> is configured to receive the first signal. Although external device <b>18</b> transmits the first signal according to the first protocol, IMD <b>16</b> is not configured to, in some examples, communicate (including transmitting and receiving information) according to the first protocol. However, the signal reception circuitry (not illustrated in <figref idref="DRAWINGS">FIG. <b>1</b></figref>) of IMD <b>16</b> is configured to detect electromagnetic field variations, wherein the electromagnetic variations may be induced by TCC signals, magnetic induction signals, RF signals, or other kinds of signals. As such, IMD <b>16</b> is configured to detect the first signal, since the first signal causes electromagnetic field variations within the first range of external device <b>18</b>. In fact, IMD <b>16</b> may be configured to detect one or more parameters of the first signal based on the electromagnetic field variations, such as the first frequency value, the second frequency value, the first duration, the second duration, and the total duration.
0044In some examples, IMD <b>16</b> is configured to cross-reference values of the one or more detected parameters of the first signal with one or more baseline values of the detected parameters, where the one or more baseline values are stored in a memory of IMD <b>16</b>. Subsequently, IMD <b>16</b> is configured to determine if the first signal matches an expected first signal associated with external device <b>18</b>. In response to determining that external device <b>18</b> transmitted the first signal, IMD <b>16</b> is configured to transmit, via the communication circuitry of IMD <b>16</b>, a second signal to the external device according to the second protocol. The second signal may include a set of advertisements for establishing the secure link. The second protocol, which is different than the first protocol, may be communication protocol known to both IMD <b>16</b> and external device <b>18</b>. In some examples, the second protocol includes a Bluetooth® protocol such as a Bluetooth® Low Energy (BTLE) protocol.
0045A device (e.g., IMD <b>16</b>, external device <b>18</b>, or external device <b>20</b>) may be configured to transmit signals according to the second protocol while the device is operating in a reduced power mode or a normal power mode. In some examples, when transmitting signals according to the second protocol and while operating in the normal power mode, the device may transmit signals at 0 decibels with reference to one milliwatt (dBm). Additionally, in some examples, when transmitting signals according to the second protocol and while operating in the reduced power mode, the device may transmit signals at −20 dBm. In other words, a power magnitude of signals transmitted while the device is operating in the reduced power mode may be decreased a hundredfold from a power magnitude of signals transmitted while the device is operating in the normal power mode. In other examples, when transmitting signals according to the second protocol and while operating in the reduced power mode, the device may transmit signals within a range from −50 dBm to −10 dBm.
0046The second signal transmitted by IMD <b>16</b> may include a set of advertisements transmitted at the second advertisement rate. In some examples, prior to transmitting the second signal at the second advertisement rate in response to receiving the first signal, IMD <b>16</b> may transmit advertisements at the first advertisement rate, where the first advertisement rate is less than the second advertising rate. In other examples, prior to transmitting the second signal at the second advertisement rate, the communication circuitry of IMD <b>16</b> is powered off and IMD <b>16</b> does not transmit advertisements. In such examples, the second advertisement rate may be the only rate in which IMD <b>16</b> transmits advertisements. External device <b>18</b> is configured to receive the second signal including the set of advertisements. Subsequently, in some examples, external device <b>18</b> is configured to generate a first set of random data. In other examples, external device <b>18</b> may transmit, via communication link <b>24</b>, a notification to external device <b>20</b> that the second signal is received and external device <b>20</b> generates the first set of random data. External devices <b>18</b>, <b>20</b> may transmit the first set of random data to IMD <b>16</b>, and in response to receiving the first set of random data, IMD <b>16</b> may generate a second set of random data. In some examples, the first set of random data and the second set of random data each include a 64-bit integer.
0047IMD <b>16</b> may be configured to store an encrypted form of a first encryption key and a non-encrypted form of the first encryption key. The first encryption key may, in some cases, be a “device key” that is created and stored in IMD <b>16</b> at a time when IMD <b>16</b> is manufactured. In some examples, the encrypted form of the first encryption key is encrypted using a public key of the ECIES security algorithm. After generating the second set of random data, IMD <b>16</b> is configured to transmit the second set of random data, a challenge, and the encrypted form of the first encryption key to external device <b>18</b>. IMD <b>16</b> may transmit the second set of random data, the challenge, and the encrypted form of the first encryption key according to the second protocol, but with reduced power relative to subsequent communication according to the second protocol. In some examples, e.g., where the IMD <b>16</b> uses reduced power, IMD <b>16</b> transmits the second set of random data, the challenge, and the encrypted form of the first encryption key having a power magnitude of less than about 150 nanowatts (nW). To improve security by limiting the range in which a device is configured to intercept the second set of random data, the challenge, and the encrypted form of the first encryption key, it may be desirable to transmit with reduced power, e.g., defining a maximum range of about 1 meter.
0048The challenge includes, in some cases, a non-encrypted 64-bit integer. IMD <b>16</b> may store the challenge in a memory as a template challenge for future verification. Additionally, in some examples, IMD <b>16</b> is configured to calculate a second encryption key based on the first set of random data, the second set of random data, and the non-encrypted form of the first encryption key.
0049External device <b>18</b> may receive the second set of random data, the challenge, and the encrypted form of the first encryption key. In some examples, external device <b>18</b> relays the second set of random data, the challenge, and the encrypted form of the first encryption key to external device <b>20</b> via communication link <b>24</b>. Each of IMD <b>16</b>, external device <b>18</b>, and external device <b>20</b> are configured to commit the first set of random data and the second set of random data to respective memories. Any combination of external device <b>18</b> and external device <b>20</b> are configured to decrypt the first encryption key using, in some examples, a private key of the ECIS security algorithm. As such, external devices <b>18</b>, <b>20</b> are configured to obtain the non-encrypted form of the first encryption key. External devices <b>18</b>, <b>20</b> may calculate the second encryption key based on the first set of random data, the second set of random data, and the non-encrypted form of the first encryption key. Thus, IMD <b>16</b> and external devices <b>18</b>, <b>20</b> may each calculate the second configuration independently of each other. The independent generation of the second encryption key ensures that the second encryption key does not need to be wirelessly transmitted between IMD <b>16</b> and external devices <b>18</b>, <b>20</b> therefore decreasing a probability that the second encryption key is intercepted or otherwise compromised.
0050In some examples, external devices <b>18</b>, <b>20</b> are configured to encrypt, using the second encryption key, the challenge received from IMD <b>16</b>. External device <b>18</b> may transmit the encrypted challenge to IMD <b>16</b>. Since IMD <b>16</b> is configured to calculate the second encryption key independently from external devices <b>18</b>, <b>20</b>, IMD <b>16</b> may decrypt the encrypted challenge using the second encryption key. To verify the encrypted challenge transmitted by external device <b>18</b> and decrypted by IMD <b>16</b>, IMD <b>16</b> is configured to cross-reference the challenge received from external device <b>18</b> with the template challenge, where the template challenge corresponds to the challenge originally sent to external device <b>18</b>. In other words, transmitting the challenge to external device <b>18</b> and receiving the encrypted challenge from external device <b>18</b> enables IMD <b>16</b> to verify that external devices <b>18</b>, <b>20</b> possess the second encryption key.
0051IMD <b>16</b> is configured to transmit a verification signal to external device <b>18</b> which establishes a secure link between IMD <b>16</b> and external devices <b>18</b>, <b>20</b>. In some examples, communications transmitted over the secure link are at the normal power mode of the second protocol. External device <b>18</b> is configured to receive the verification signal, and in some cases add external device <b>20</b> to the secure link, thus enabling both of external device <b>18</b> and external device <b>20</b> to communicate with IMD <b>16</b> over the secure link. In one example, external device <b>18</b> communicates with external device <b>20</b> over a secure channel of communication link <b>24</b> and also communicates with IMD <b>16</b> over a secure channel of communication link <b>22</b>. As such, in this example, external device <b>18</b> acts as an intermediary between external device <b>20</b> and IMD <b>16</b>, therefore establishing an indirect secure link between external device <b>20</b> and IMD <b>16</b>.
0052In some cases, it may be desirable to terminate a secure link between any combination of IMD <b>16</b>, external device <b>18</b>, and external device <b>20</b>. A secure link between external device <b>20</b> and IMD <b>16</b> may be terminated if any one of IMD <b>16</b>, external device <b>18</b>, or external device <b>20</b> outputs an instruction to terminate the secure link. Additionally, in examples where external device <b>18</b> acts as an intermediary between external device <b>20</b> and IMD <b>16</b>, if external device <b>18</b> exits a range required to communicate with either IMD <b>16</b> or external device <b>20</b>, the secure link is terminated. In some examples, after a secure link with IMD <b>16</b> is established by external device <b>18</b>, a time window is started, where the time window is set to expire after a predetermined amount of time. If the time window expires before the secure link is terminated, IMD <b>16</b> may terminate the secure link. In some examples, the predetermined amount of time is about one hour.
0053In some examples, any combination of IMD <b>16</b>, external device <b>18</b>, external device <b>20</b>, or other external devices (not illustrated in <figref idref="DRAWINGS">FIG. <b>1</b></figref>) create a set of additional encryption keys using the second encryption key. Each additional encryption key of the set of additional encryption keys may enable the encryption and decryption of a particular class of data. For example, one additional encryption key may enable the encryption and decryption of physiological data stored in IMD <b>16</b>.
0054In some examples, a power magnitude of transmissions made over the secure link is greater than a power magnitude of the second set of random data, the challenge, and the encrypted form of the first encryption key sent by IMD <b>16</b> to external device <b>18</b> as part of the key generation process.
0055Although external device <b>18</b> and external device <b>20</b> are illustrated in <figref idref="DRAWINGS">FIG. <b>1</b></figref> as being separate devices, in some examples (not illustrated), a single external device performs the functions of both external device <b>18</b> and external device <b>20</b>.
0056Although in one example IMD <b>16</b> takes the form of an ICM, in other examples, IMD <b>16</b> takes the form of any combination of implantable cardioverter defibrillators (ICDs), pacemakers, cardiac resynchronization therapy devices (CRT-Ds), spinal cord stimulation (SCS) devices, deep brain stimulation (DBS) devices, left ventricular assist devices (LVADs), implantable sensors, orthopedic devices, or drug pumps, as examples. Moreover, techniques of this disclosure may be used to establish secure connections with any one of the aforementioned IMDs. Moreover, techniques described in this disclosure may be applied to establish a secure link between two or more devices, where none of the two or more devices are implantable devices. Additionally, in some examples, techniques described in this disclosure may be applied to establish a secure link between two or more devices, where none of the two or more devices are medical devices.
0057<figref idref="DRAWINGS">FIG. <b>2</b></figref> is a block diagram illustrating an example configuration of components of IMD <b>16</b> in accordance with one or more techniques of this disclosure. In the example of <figref idref="DRAWINGS">FIG. <b>2</b></figref>, IMD <b>16</b> includes processing circuitry <b>30</b>, sensing circuitry <b>32</b>, electrodes <b>34</b>A-<b>34</b>D (collectively, “electrodes <b>34</b>”), sensors <b>35</b>, switching circuitry <b>36</b>, signal reception circuitry <b>37</b>, communication circuitry <b>38</b>, antenna <b>39</b>, memory <b>40</b>, and power source <b>48</b>. Memory <b>40</b> is configured to store communication protocols <b>42</b>, operational parameters <b>44</b>, collected data <b>45</b>, and encryption keys <b>46</b>.
0058Processing circuitry <b>30</b>, in one example, may include one or more processors that are configured to implement functionality and/or process instructions for execution within IMD <b>16</b>. For example, processing circuitry <b>30</b> may be capable of processing instructions stored in memory <b>40</b>. Processing circuitry <b>30</b> may include, for example, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or equivalent discrete or integrated logic circuitry, or a combination of any of the foregoing devices or circuitry. Accordingly, processing circuitry <b>30</b> may include any suitable structure, whether in hardware, software, firmware, or any combination thereof, to perform the functions ascribed herein to processing circuitry <b>30</b>.
0059Sensing circuitry <b>32</b> monitors electrical cardiac signals from any combination of electrodes <b>34</b>A-<b>34</b>D (collectively, “electrodes <b>34</b>”). In some examples, sensing circuitry <b>32</b> may include one or more amplifiers, filters, and analog-to-digital converters. For example, sensing circuitry <b>32</b> may include one or more detection channels, each of which may include an amplifier. The detection channels may be used to sense cardiac signals, such as a cardiac EGM. Some detection channels may detect events, such as R-waves, P-waves, and T-waves and provide indications of the occurrences of such events to processing circuitry <b>30</b>. Additionally, or alternatively, some channels may detect cardiac EGM signals from a particular combination of electrodes <b>34</b>. One or more other detection channels may provide signals to an analog-to-digital converter, for conversion into a digital signal for processing, analysis, storage, or output by processing circuitry <b>30</b>.
0060Each detection channel of sensing circuitry <b>32</b> may include a filter configured to pass a custom range of frequency values. For example, sensing circuitry <b>32</b> may include one or more narrow band channels, each of which may include a narrow band filtered sense-amplifier. Additionally, or alternatively, sensing circuitry <b>32</b> may include one or more wide band channels, each of which include an amplifier with a relatively wider pass band than the narrow band channels. Signals sensed by the narrow band channels and the wide band channels of sensing circuitry <b>32</b> may be converted to multi-bit digital signals by an analog-to-digital converter (ADC) provided by, for example, sensing circuitry <b>32</b> or processing circuitry <b>30</b>. In some examples, processing circuitry <b>30</b> analyzes the digitized version of signals from sensing circuitry <b>32</b>. In other examples, processing circuitry <b>30</b> stores the digitized versions of the signals in memory <b>40</b> (e.g., as collected data <b>45</b>), outputs the digitized versions of the signals via communication circuitry <b>38</b>, or any combination thereof.
0061Processing circuitry <b>30</b> may use switching circuitry <b>36</b> to select, e.g., via a data/address bus, which of electrodes <b>34</b> to use for sensing cardiac signals. Switching circuitry <b>36</b> may include a switch array, switch matrix, multiplexer, or any other type of switching device suitable to selectively couple energy to selected electrodes.
0062In some examples, sensing circuitry <b>32</b> is electrically coupled to sensors <b>35</b>. Sensors <b>35</b> may include any combination of accelerometers, temperature sensors, chemical sensors, light sensors, and pressure sensors. Sensors <b>35</b> may, for example, sense one or more physiological parameters indicative of a heart condition. Additionally, or alternatively, an accelerometer of sensors <b>35</b> may sense data indicative of at least one of patient posture and patient activity.
0063Signal reception circuitry <b>37</b> may include hardware, firmware, software or any combination thereof for receiving signals from another device, such as external device <b>18</b> or external device <b>20</b>. For example, signal reception circuitry <b>37</b> may be configured to detect electromagnetic variations indicative of a signal. In some cases, the signal may include a TCC signal. In such cases, signal reception circuitry <b>37</b> may include circuitry configured for detecting electromagnetic field variations indicative of the TCC signal. Signal reception circuitry <b>37</b> may be powered by power source <b>48</b>, “listening” for signals from external device <b>18</b> or external device <b>20</b>. In other examples, power source <b>48</b> may power signal reception circuitry <b>37</b> every 250 ms for a period of time, where the period of time lasts for greater than 0.1 ms and less than 50 ms. In this way, signal reception circuitry <b>37</b> may alternate between an “off” state and an “on” state, where signal reception circuitry <b>37</b> is configured to detect signals while signal reception circuitry <b>37</b> is being powered by power source <b>48</b> during the on state.
0064Communication circuitry <b>38</b> may include any suitable hardware, firmware, software or any combination thereof for communicating with another device, such as external device <b>18</b> or external device <b>20</b>. Under the control of processing circuitry <b>30</b>, communication circuitry <b>38</b> may receive downlink telemetry from, as well as send uplink telemetry to, external device <b>18</b>, external device <b>20</b>, or another device with the aid of an internal or external antenna, e.g., antenna <b>39</b>. In addition, processing circuitry <b>30</b> may communicate with a networked computing device via an external device (e.g., external device <b>18</b>) and a computer network, such as the Medtronic CareLink® Network developed by Medtronic, plc, of Dublin, Ireland. Communication circuitry <b>38</b> may include any combination of a Bluetooth® radio, an electronic oscillator, frequency modulation circuitry, frequency demodulation circuitry, amplifier circuitry, and power switches such as a metal-oxide-semiconductor field-effect transistors (MOSFET), a bipolar junction transistor (BJT), an insulated-gate bipolar transistor (IGBT), a junction field effect transistor (JFET), or another element that uses voltage for its control. In examples in which IMD <b>16</b> receives the first signal from external device <b>18</b> via tissue conductance communication, communication circuitry <b>38</b> may receive the first signal via one or more of electrodes <b>34</b>. Signal reception circuitry <b>37</b> may, in some cases, be separate from communication circuitry <b>38</b>. In other cases, signal reception circuitry <b>37</b> may be a component of, or a part of communication circuitry <b>38</b>.
0065Memory <b>40</b> may be configured to store information within IMD <b>16</b> during operation. Memory <b>40</b> may include a computer-readable storage medium or computer-readable storage device. In some examples, memory <b>40</b> includes one or more of a short-term memory or a long-term memory. Memory <b>40</b> may include, for example, random access memories (RAM), dynamic random access memories (DRAM), static random access memories (SRAM), magnetic discs, optical discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable memories (EEPROM). In some examples, memory <b>40</b> is used to store data indicative of instructions for execution by processing circuitry <b>30</b>.
0066In some examples, memory <b>40</b> is configured to store one or more communication protocols <b>42</b>. Each protocol of communication protocols <b>42</b> may define a set of rules that govern one or more aspects of data exchange between IMD <b>16</b> and other devices (e.g., external device <b>18</b> and external device <b>20</b>. In some examples, communication protocols <b>42</b> are stored as lists of computer-readable instructions and communication protocols may be executed by any combination of hardware (e.g., processing circuitry <b>30</b>) and software. In some examples, communication protocols <b>42</b> includes a Bluetooth® protocol such as a BTLE protocol. In some examples, communication protocols <b>42</b> exclusively include the Bluetooth® protocol. Alternatively, in other examples, communication protocols <b>42</b> may include any combination of Bluetooth® protocols, protocols developed by the manufacturer of IMD <b>16</b>, and protocols licensed from a third-party developer.
0067In some examples, memory <b>40</b> is configured to store operational parameters <b>44</b>. Operational parameters <b>44</b> may govern aspects of the operation of IMD <b>16</b>. For example, operational parameters <b>44</b> may include combinations of electrodes <b>34</b> and sensors <b>35</b> for sensing physiological signals of patient <b>4</b>. Additionally, or alternatively, operational parameters <b>44</b> may include a sampling rate for sampling analog signals sensed by electrodes <b>34</b> and sensors <b>35</b>. Operational parameters <b>44</b> may be updated based on instructions received from an external device (e.g., external device <b>20</b>) via communication circuitry <b>38</b>. In some examples, processing circuitry <b>30</b> of IMD <b>16</b> updates operational parameters <b>44</b> only if instructions to update operational parameters <b>44</b> are received over a secure link.
0068In some examples, memory <b>40</b> is configured to store collected data <b>45</b>. Collected data <b>45</b> may include any data sensed, processed, or analyzed by IMD <b>16</b>, where the data is acquired via any combination of electrodes <b>34</b>, sensors <b>35</b>, signal reception circuitry <b>37</b> and communication circuitry <b>38</b>. In some examples, collected data <b>45</b> includes a cardiac EGM recording sensed by sensing circuitry <b>32</b> via electrodes <b>34</b> and processed by processing circuitry <b>30</b>. Additionally, or alternatively, collected data <b>45</b> may include data acquired by one or more chemical sensors of sensors <b>35</b>, where the data is indicative of a presence of or a possibility of at least one heart condition (e.g., heart failure). Thus, in general, collected data <b>45</b> may represent physiological signals acquired from patient <b>4</b> over a period of time. In some examples, the period of time lasts for greater than 12 hours and less than 72 hours. In other examples, the period of time lasts for up to one month. Put another way, IMD <b>16</b> is configured to continuously monitor physiological signals over the period of time and store at least some of these physiological signals in memory <b>40</b> as collected data <b>45</b>.
0069Collected data <b>45</b> may include sensitive information. Thus, it may be desirable to restrict the access of collected data <b>45</b> to patient <b>4</b> and clinicians responsible for the medical care of patient <b>4</b>. For at least these reasons, if a portion of collected data <b>45</b> is transmitted from IMD <b>16</b> to another device (e.g., external device <b>18</b> or external device <b>20</b>), processing circuitry <b>30</b> may transmit the portion of collected data <b>45</b> over a secure link (e.g., an encrypted link). To transmit data over the secure link, processing circuitry <b>30</b> may encode data using one or more of encryption keys <b>46</b> stored in memory <b>40</b>. By the same token, processing circuitry may decode encrypted data received by IMD <b>16</b> from other devices using encryption keys <b>46</b>. At least one of encryption keys <b>46</b> may include an advanced encryption standard (AES) key which defines a 128-bit integer. In some examples, to improve security measures, IMD <b>16</b> only transmits collected data <b>45</b> via encrypted communication links. Additionally, in some examples, encryption keys <b>46</b> include an encrypted form of a device key and a non-encrypted form of the device key. The device key may represent a key that is stored within memory <b>40</b> at a time that IMD <b>16</b> is manufactured. The encrypted form of the device key may be encrypted using a public key of the ECIES security algorithm.
0070Another device (e.g., external device <b>18</b>) may attempt to establish a secure link with IMD <b>16</b>. For example, signal reception circuitry <b>37</b> of IMD <b>16</b> may receive a first signal from external device <b>18</b>. The first signal, in some examples, causes processing circuitry <b>30</b> to trigger communication circuitry <b>38</b> to begin transmitting advertisements. In other examples, the first signal causes processing circuitry <b>30</b> to increase a rate in which communication circuitry <b>38</b> transmits advertisements. In examples where the first signal causes processing circuitry <b>30</b> to trigger communication circuitry <b>38</b> to begin transmitting advertisements, communication circuitry <b>38</b> may be off prior to signal reception circuitry <b>37</b> receiving the first signal. In examples where the first signal causes processing circuitry <b>30</b> to increase the advertisement rate, communication circuitry <b>38</b> may transmit advertisements at a first advertisement rate prior to IMD <b>16</b> receiving the first signal and transmit advertisements at a second advertisement rate after IMD <b>16</b> receives the first signal, where the second advertisement rate is greater than the first advertisement rate. When transmitting advertisements, communication circuitry <b>38</b> may be powered by power source <b>48</b> during the transmission of each advertisement. Additionally, communication circuitry <b>38</b> may be powered for a period of time following each advertisement in order to listen for a response to the respective advertisement. In this manner, increasing the advertisement rate may cause a rate in which power is drained from power source <b>48</b> to increase.
0071Communication protocols <b>42</b> may include one or more protocols and may enable IMD <b>16</b> to communicate according to a Bluetooth® protocol, as an example. However, in some examples, the first signal is transmitted according to a communication protocol other than the Bluetooth® protocol, where the communication protocol is unknown to IMD <b>16</b> (e.g., the communication protocol is not included in communication protocols <b>42</b> stored by memory <b>40</b>. Even if the communication protocol of the first signal is not known to IMD <b>16</b>, signal reception circuitry <b>37</b> may, for example, sense the first signal by detecting electromagnetic field variations associated with the first signal. Moreover, processing circuitry <b>30</b> may process the first signal to determine one or more parameters of the first signal such as frequency components or signal duration. Based comparing the one or more parameters of the detected signal with one or more known parameters stored by memory <b>40</b>, processing circuitry <b>30</b> may verify that the first signal was transmitted by a trusted device (e.g., external device <b>18</b>).
0072IMD <b>16</b> may be configured to transmit a second signal to external device <b>18</b> via communication circuitry <b>38</b> according to one of communication protocols <b>42</b>. As such, the second signal is transmitted from IMD <b>16</b> to external device <b>18</b> according to a different communication protocol than the communication protocol associated with first signal received by IMD <b>16</b> response to receiving the first signal. The communication protocol of communication protocols <b>42</b> used to transmit the second signal may be the BTLE protocol operating in the normal power mode. In some examples, the second signal includes a set of advertisements which are transmitted by IMD <b>16</b> at a second advertisement rate, where the second advertisement rate is significantly higher than the first advertisement rate in which communication circuitry <b>38</b> transmits advertisements before IMD <b>16</b> receives the first signal. In other examples, communication circuitry <b>38</b> does not transmit advertisements before IMD <b>16</b> receives the first signal, and communication circuitry <b>38</b> transmits the second signal including set of advertisements at the second advertisement rate after IMD <b>16</b> receives the first signal.
0073In response to transmitting the second signal, IMD <b>16</b> may receive, in some examples, a first set of random data from external device <b>18</b>. In other examples, IMD <b>16</b> receives the first set of random data from external device <b>20</b> over communication link <b>26</b>. Subsequently, IMD <b>16</b> may generate a second set of random data. IMD <b>16</b> is configured to transmit the second set of random data, a non-encrypted challenge, and a first encryption key to any combination of external devices <b>18</b>, <b>20</b> according to the reduced power mode of the second protocol. In some examples, IMD <b>16</b> transmits the second set of random data, the non-encrypted challenge, and the first encryption key, where the transmission has a signal strength of less than about 150 nW. Transmitting the second set of random data, the non-encrypted challenge, and the first encryption key at less than about 150 nW may limit the range of the transmission to about 1 meter, thus decreasing a probability that the second set of random data, the non-encrypted challenge, or the first encryption key could be intercepted by an untrusted device other than external device <b>18</b> and external device <b>20</b>. In some examples, the first encryption key includes the encrypted form of the device key that is stored in memory <b>40</b> as part of encryption keys <b>46</b>. Using the first set of random data, the second set of random data, and the non-encrypted form of the device key, IMD <b>16</b> may generate a second encryption key. The second encryption key may be a 128-bit “session” key that enables IMD <b>16</b> to encrypt and decrypt data exchanged with external device <b>18</b> and/or external device <b>20</b>. IMD <b>16</b> may store the second encryption key in memory <b>40</b> as part of encryption keys <b>46</b>.
0074IMD <b>16</b> may receive an encrypted challenge from either external device <b>18</b> or external device <b>20</b>, and IMD <b>16</b> may decrypt the encrypted challenge using the second encryption key. To verify the challenge, IMD <b>16</b> may cross-reference the challenge received from either external device <b>18</b> or external device <b>20</b> with the non-encrypted challenge originally sent to external device <b>18</b>. After verifying the challenge, IMD <b>16</b> is configured to transmit a verification signal and establish a secure link with external device <b>18</b> and/or external device <b>20</b>.
0075The second encryption key may be set to expire after a period of time. In some examples, IMD <b>16</b> starts a time window after establishing a secure link, where the time window is set to expire after a predetermined amount of time. When the time window expires, IMD <b>16</b> terminates the secure link. After a secure link is established between IMD <b>16</b> and another device such as external device <b>18</b> and/or external device <b>20</b>, IMD <b>16</b> may send and receive data over the secure link. IMD <b>16</b> may, for example, receive encrypted data indicative of instructions from external device <b>20</b>. As such, processing circuitry <b>30</b> may use encryption keys <b>46</b> (e.g., the second encryption key) to decode the encrypted data and implement the instructions in IMD <b>16</b>. For example, the instructions may include a request for IMD <b>16</b> to output at least some of collected data <b>45</b>. Additionally, or alternatively, the instructions may cause processing circuitry <b>30</b> to record patient data using a particular combination of electrodes <b>34</b> and sensors <b>35</b>. The instructions may also include a request for IMD <b>16</b> to output other information, such as a battery life of power source <b>48</b>, or impedance values of electrodes <b>34</b>.
0076Secure communications between IMD <b>16</b> and other devices may occur according to at least one of communication protocols <b>42</b>. As such, other devices communicating with IMD <b>16</b> may concurrently be configured with least one of communication protocols <b>42</b>.
0077Power source <b>48</b> is configured to deliver operating power to the components of IMD <b>16</b>. Power source <b>48</b> may include a battery and a power generation circuit to produce the operating power. In some examples, the battery is rechargeable to allow extended operation. In some examples, recharging is accomplished through proximal inductive interaction between an external charger and an inductive charging coil within external device <b>18</b>. Power source <b>48</b> may include any one or more of a plurality of different battery types, such as nickel cadmium batteries and lithium ion batteries.
0078<figref idref="DRAWINGS">FIG. <b>3</b></figref> is a block diagram illustrating an example configuration of components of external device <b>18</b> in accordance with one or more techniques of this disclosure. In the example of <figref idref="DRAWINGS">FIG. <b>3</b></figref>, external device <b>18</b> includes processing circuitry <b>60</b>, communication circuitry <b>62</b>, memory <b>64</b>, user interface <b>72</b>, and power source <b>74</b>. Memory <b>64</b> is configured to store signal program <b>66</b>, communication protocols <b>68</b>, and encryption keys <b>70</b>.
0079Processing circuitry <b>60</b>, in one example, may include one or more processors that are configured to implement functionality and/or process instructions for execution within external device <b>18</b>. For example, processing circuitry <b>60</b> may be capable of processing instructions stored in memory <b>64</b>. Processing circuitry <b>60</b> may include, for example, microprocessors, DSPs, ASICs, FPGAs, or equivalent discrete or integrated logic circuitry, or a combination of any of the foregoing devices or circuitry. Accordingly, processing circuitry <b>60</b> may include any suitable structure, whether in hardware, software, firmware, or any combination thereof, to perform the functions ascribed herein to processing circuitry <b>60</b>.
0080Communication circuitry <b>62</b> may include any suitable hardware, firmware, software or any combination thereof for communicating with another device, such as IMD <b>16</b> or external device <b>20</b>. Under the control of processing circuitry <b>60</b>, communication circuitry <b>62</b> may receive downlink telemetry from, as well as send uplink telemetry to, IMD <b>16</b>, external device <b>20</b>, or another device. In addition, processing circuitry <b>30</b> may communicate with a computer network, such as the Medtronic CareLink® Network developed by Medtronic, plc, of Dublin, Ireland. Communication circuitry <b>62</b> may include any combination of a Bluetooth® radio, an electronic oscillator, frequency modulation circuitry, frequency demodulation circuitry, amplifier circuitry, and power switches such as a MOSFET, a BJT, an IGBT, a JFET, or another element that uses voltage for its control. Communication circuitry <b>64</b> may transmit and receive signals via an antenna, e.g., for radiofrequency communication, and/or electrodes for tissue conductance communication.
0081Memory <b>64</b> may be configured to store information within external device <b>18</b> during operation. Memory <b>64</b> may include a computer-readable storage medium or computer-readable storage device. In some examples, memory <b>64</b> includes one or more of a short-term memory or a long-term memory. Memory <b>64</b> may include, for example, RAM, DRAM, SRAM, magnetic discs, optical discs, flash memories, or forms of EPROM or EEPROM. In some examples, memory <b>64</b> is used to store data indicative of instructions for execution by processing circuitry <b>60</b>. Memory <b>64</b> may be used by software or applications running on external device <b>18</b> to temporarily store information during program execution.
0082In some examples, external device <b>18</b> is used to establish a secure connection with IMD <b>16</b>. For instance, example techniques of this disclosure enable IMD <b>16</b> to transmit, via communication circuitry <b>62</b>, a signal to IMD <b>16</b>. The signal may represent a wake-up signal for initiating the establishment of a secure link. Processing circuitry <b>60</b> is configured to generate the signal based on signal program <b>66</b>. In some examples, external device <b>18</b> transmits the signal in response to receiving an instruction from external device <b>20</b>. In other examples, external device <b>18</b> transmits the signal based on user input to user interface <b>72</b>.
0083Memory <b>64</b> is configured to store signal program <b>66</b>. Signal program <b>66</b> may include a list of computer readable instructions which cause processing circuitry <b>60</b> to generate the signal, where the signal includes a plurality of primary portions defining a first frequency value and a first duration and a plurality of secondary portions defining a second frequency value and a second duration. Processing circuitry <b>60</b> is configured to interleave the plurality of primary portions and the plurality of secondary portions such that one primary portion occurs between two consecutive secondary portions and one secondary portion occurs between two consecutive primary portions. However, the first and last frequency portions, whether they are primary portions or secondary portions, are bounded by one frequency portion. In some examples, the first frequency value is about 200 kilohertz (kHz), the second frequency value is about 150 kHz, and the first duration and the second duration are each about 80 microseconds (μs). However, these values are not meant to be limiting. The first frequency value, the second frequency value, the first duration, and the second duration may include any value or range of values. As such, external device <b>18</b> is configured to generate the first signal which is defined by an electromagnetic waveform which alternates between two frequency values.
0084Processing circuitry <b>60</b> may transmit, via communication circuitry <b>62</b>, the signal generated by external device <b>18</b> based on signal program <b>66</b> to IMD <b>16</b>. Processing circuitry <b>60</b> may transmit the signal according to at least one of communication protocols <b>68</b> stored by memory <b>64</b>. In some examples, at least some of communication protocols <b>68</b> are not included in communication protocols <b>42</b> of <figref idref="DRAWINGS">FIG. <b>1</b></figref>. Put another way, external device <b>18</b> may have access to at least one communication protocol that is not available to IMD <b>16</b>. In some examples, processing circuitry <b>60</b> transmits the signal generated based on signal program <b>66</b> to IMD <b>16</b> according to a communication protocol that is not available to IMD <b>16</b>. In some examples, the protocol includes any communication protocol which uses magnetic induction communication, RF communication, or tissue conductance communication.
0085After transmitting the signal, external device <b>18</b> may receive a subsequent signal from IMD <b>16</b> which includes a set of advertisements, where the subsequent signal is received by external device <b>18</b> according to at least one of communication protocols <b>68</b>. In some examples, the subsequent signal is received according to the BTLE protocol and a power of the subsequent signal may be less than about 150 nW. In some examples, external device <b>18</b> relays the set of advertisements to external device <b>20</b>. Any combination of processing circuitry <b>60</b> of external device <b>18</b> and processing circuitry <b>80</b> of external device <b>20</b> is configured to generate a first set of random data and transmit the first set of random data to IMD <b>16</b> according to a communication protocol of communication protocols <b>68</b>, where the communication protocol is concurrently stored in memory <b>40</b> of IMD <b>16</b>. In examples where external device <b>20</b> generates the first set of random data, external device <b>18</b> may relay the first set of random data from external device <b>20</b> to IMD <b>16</b>.
0086After the first set of random data is transmitted to IMD <b>16</b>, external device <b>18</b> may receive a second set of random data, a non-encrypted challenge, and an encrypted form of a first encryption key from IMD <b>16</b>. In some examples, external device <b>18</b> in turn transmits the second set of random data, a non-encrypted challenge, and an encrypted form of a first encryption key to external device <b>20</b>. As such, any combination of external devices <b>18</b>, <b>20</b> may decrypt the first encryption key to obtain a non-encrypted form of the first encryption key. In some examples, external devices <b>18</b>, <b>20</b> calculate a second encryption key based on the first set of random data, the second set of random data, and the non-encrypted form of the first encryption key. Additionally, external devices <b>18</b>, <b>20</b> may encrypt the challenge and transmit the encrypted challenge to IMD <b>16</b>. If IMD <b>16</b> is able to verify the challenge, external device <b>18</b> may receive a verification signal from IMD <b>16</b> and establish a secure link with IMD <b>16</b>. After establishing the secure link, external device <b>18</b> is configured to, in one example, relay data between external device <b>20</b> and IMD <b>16</b> using secure connections.
0087A user, such as a clinician or patient <b>4</b>, may interact with external device <b>18</b> through user interface <b>72</b>. User interface <b>72</b> may include an input mechanism to receive input from the user. The input mechanisms may include, for example, any one or more of buttons, a keypad (e.g., an alphanumeric keypad), a peripheral pointing device, a touch screen, or another input mechanism that allows the user to navigate through user interfaces presented by processing circuitry <b>60</b> of external device <b>18</b> and provide input. In one example, user interface <b>72</b> includes a single button which enables the user to instruct external device <b>18</b> to execute one or more actions. In other examples, user interface <b>72</b> also includes audio circuitry for accepting audio instructions.
0088Power source <b>74</b> is configured to deliver operating power to the components of external device <b>18</b>. Power source <b>74</b> may include a battery and a power generation circuit to produce the operating power. In some examples, the battery is rechargeable to allow extended operation. Recharging may be accomplished by electrically coupling power source <b>74</b> to a cradle or plug that is connected to an alternating current (AC) outlet. In addition, recharging may be accomplished through proximal inductive interaction between an external charger and an inductive charging coil within external device <b>18</b>. In other examples, traditional batteries (e.g., nickel cadmium or lithium ion batteries) may be used. In addition, external device <b>18</b> may be directly coupled to an alternating current outlet to operate.
0089<figref idref="DRAWINGS">FIG. <b>4</b></figref> is a block diagram illustrating an example configuration of components of external device <b>20</b> in accordance with one or more techniques of this disclosure. In the example of <figref idref="DRAWINGS">FIG. <b>4</b></figref>, external device <b>20</b> includes processing circuitry <b>80</b>, communication circuitry <b>82</b>, memory <b>84</b>, user interface <b>92</b>, and power source <b>94</b>. Memory <b>84</b> is configured to store communication protocols <b>86</b>, encryption keys <b>88</b>, operational parameters <b>90</b>, and retrieved data <b>91</b>.
0090Processing circuitry <b>80</b>, in one example, may include one or more processors that are configured to implement functionality and/or process instructions for execution within external device <b>20</b>. For example, processing circuitry <b>80</b> may be capable of processing instructions stored in memory <b>84</b>. Processing circuitry <b>80</b> may include, for example, microprocessors, DSPs, ASICs, FPGAs, or equivalent discrete or integrated logic circuitry, or a combination of any of the foregoing devices or circuitry. Accordingly, processing circuitry <b>80</b> may include any suitable structure, whether in hardware, software, firmware, or any combination thereof, to perform the functions ascribed herein to processing circuitry <b>80</b>.
0091Communication circuitry <b>82</b> may include any suitable hardware, firmware, software or any combination thereof for communicating with another device, such as IMD <b>16</b> or external device <b>18</b>. Under the control of processing circuitry <b>80</b>, communication circuitry <b>82</b> may receive downlink telemetry from, as well as send uplink telemetry to, IMD <b>16</b>, external device <b>18</b>, or another device. In some examples, communication circuitry <b>82</b> includes a first set of communication circuitry configured for transmitting and receiving signals according to a communication protocol developed by the manufacturer of IMD <b>16</b> or a third-party developer. In some such examples, communication circuitry <b>82</b> further includes a second set of communication circuitry which defines a Bluetooth® radio configured for transmitting and receiving signals according to Bluetooth® communication protocols. However, communication circuitry <b>82</b> does not necessarily include separate sets of circuitry corresponding to different communication protocols. In some examples, communication circuitry <b>82</b> includes a single set of circuitry configured for transmitting and receiving signals according to a plurality of communication protocols.
0092In some examples, communication circuitry <b>82</b> includes any combination of a Bluetooth® radio, an electronic oscillator, frequency modulation circuitry, frequency demodulation circuitry, amplifier circuitry, and power switches such as a MOSFET, a BJT, an IGBT, a JFET, or another element that uses voltage for its control.
0093Memory <b>84</b> may be configured to store information within external device <b>20</b> during operation. Memory <b>84</b> may include a computer-readable storage medium or computer-readable storage device. In some examples, memory <b>84</b> includes one or more of a short-term memory or a long-term memory. Memory <b>84</b> may include, for example, RAM, DRAM, SRAM, magnetic discs, optical discs, flash memories, or forms of EPROM or EEPROM. In some examples, memory <b>84</b> is used to store data indicative of instructions for execution by processing circuitry <b>80</b>. Memory <b>84</b> may be used by software or applications running on external device <b>20</b> to temporarily store information during program execution.
0094External device <b>20</b> may exchange information with other devices via communication circuitry <b>82</b> according to one or more communication protocols <b>86</b>. Communication protocols <b>86</b>, stored in memory <b>84</b>, may include sets of computer-readable instructions that determine how data is transmitted and processed. Communication protocols <b>86</b> may include one or more communication protocols that are additionally included in each of communication protocols <b>42</b> and communication protocols <b>68</b>. In other words, IMD <b>16</b>, external device <b>18</b>, and external device <b>20</b> may be configured to exchange information according to at least one common communication protocol. In some examples, the one or more common communication protocols include at least one Bluetooth® communication protocol. Additionally, or alternatively, communication protocols <b>86</b> may include a set of communication protocols that are not available to at least one of IMD <b>16</b> and external device <b>18</b>. In some examples, external device <b>20</b> is a consumer electronics device, such as a smartphone, a tablet, or a laptop computer. In some such examples, external device <b>20</b> may not be configured with communication protocols developed by the manufacturer of IMD <b>16</b>.
0095External device <b>20</b> may transmit data using a secure link. For example, external device <b>20</b> may use at least one of encryption keys <b>88</b> stored in memory <b>84</b> to encode data for transmission to another device via communication circuitry <b>82</b> or decode data received from another device via communication circuitry <b>82</b>. To securely transmit data to another device (e.g., IMD <b>16</b>), external device <b>20</b> may encode the data using an encryption key, where IMD <b>16</b> is configured to decode the data using another encryption key which is a counterpart of the encryption key used by external device <b>20</b>. In cases where external device <b>20</b> does not have access to an encryption key which has a counterpart stored in IMD <b>16</b>, external device <b>18</b> is configured to establish a secure link between IMD <b>16</b> and external device <b>20</b>, where external device <b>18</b> acts as an intermediary between IMD <b>16</b> and external device <b>20</b>.
0096In some examples, external device <b>20</b> calculates, using processing circuitry <b>80</b>, a “session” key, where the session key is associated with a counterpart session key stored in IMD <b>16</b>. For example, external device <b>20</b> may calculate the session key using a first set of random data, a second set of random data, and a device key. Processing circuitry <b>80</b> may, in some cases, generate the first set of random data or receive the first set of random data from external device <b>18</b> via communication circuitry <b>82</b>. Additionally, processing circuitry <b>80</b> may receive the second set of random data and the device key from IMD <b>16</b> via external device <b>18</b>. Processing circuitry <b>80</b> may store the session key in memory <b>84</b>. After creating the session key, processing circuitry <b>80</b> is configured to encode data for transmission to IMD <b>16</b> using the session key. By the same token, processing circuitry <b>80</b> is configured to decode data received from IMD <b>16</b>, the data encrypted using the counterpart session key stored by IMD <b>16</b>. In other examples, external device <b>20</b> is configured to encode data for transmission to external device <b>18</b> using an encryption key of encryption keys <b>88</b>, where the encryption key possesses a counterpart key stored in memory <b>64</b> of external device <b>18</b> as a part of encryption keys <b>70</b>. Subsequently, external device <b>18</b> may decode the data, encode the data again using a session key, and transmit the data to IMD <b>16</b> which possesses a counterpart session key. In examples where external device <b>20</b> creates the session key and in examples where external device <b>20</b> does not create the session key, external device <b>18</b> is configured to securely relay data between IMD <b>16</b> and external device <b>20</b>.
0097Data exchanged between external device <b>20</b> and IMD <b>16</b> may include any of operational parameters <b>90</b> stored in memory <b>84</b>. External device <b>20</b> may transmit data including computer readable instructions which, when implemented by IMD <b>16</b>, may control IMD <b>16</b> to change one or more operational parameters according to operational parameters <b>90</b> and/or export collected data. For example, processing circuitry <b>80</b> may transmit an instruction to IMD <b>16</b> which requests IMD <b>16</b> to export collected data (e.g., a portion of collected data <b>45</b>) to external device <b>20</b>. In turn, external device <b>20</b> may receive the collected data from IMD <b>16</b> and store the collected data in memory <b>84</b> (e.g., as retrieved data <b>91</b>). Additionally, or alternatively, processing circuitry <b>80</b> may export instructions to IMD <b>16</b> requesting IMD <b>16</b> to update electrode combinations for stimulation or sensing according to operational parameters <b>90</b>.
0098A user, such as a clinician or patient <b>4</b>, may interact with external device <b>20</b> through user interface <b>92</b>. User interface <b>92</b> includes a display (not shown), such as an LCD or LED display or other type of screen, with which processing circuitry <b>80</b> may present information related to IMD <b>16</b> (e.g., EGM signals obtained from at least one electrode or at least one electrode combination). In addition, user interface <b>92</b> may include an input mechanism to receive input from the user. The input mechanisms may include, for example, any one or more of buttons, a keypad (e.g., an alphanumeric keypad), a peripheral pointing device, a touch screen, or another input mechanism that allows the user to navigate through user interfaces presented by processing circuitry <b>80</b> of external device <b>20</b> and provide input. In other examples, user interface <b>92</b> also includes audio circuitry for providing audible notifications, instructions or other sounds to patient <b>4</b>, receiving voice commands from patient <b>4</b>, or both. Memory <b>84</b> may include instructions for operating user interface <b>92</b> and for managing power source <b>94</b>.
0099Power source <b>94</b> is configured to deliver operating power to the components of external device <b>20</b>. Power source <b>94</b> may include a battery and a power generation circuit to produce the operating power. In some examples, the battery is rechargeable to allow extended operation. Recharging may be accomplished by electrically coupling power source <b>94</b> to a cradle or plug that is connected to an alternating current (AC) outlet. In addition, recharging may be accomplished through proximal inductive interaction between an external charger and an inductive charging coil within external device <b>20</b>. In other examples, traditional batteries (e.g., nickel cadmium or lithium ion batteries) may be used. In addition, external device <b>20</b> may be directly coupled to an alternating current outlet to operate.
0100<figref idref="DRAWINGS">FIG. <b>5</b></figref> is a flow diagram illustrating an example operation in accordance with one or more techniques of this disclosure. The example operation is described with respect to IMD <b>16</b>, external device <b>18</b>, and external device <b>20</b> of <figref idref="DRAWINGS">FIGS. <b>1</b>-<b>4</b></figref>, and components thereof.
0101External device <b>18</b> is configured to generate a first signal (<b>502</b>). For example, processing circuitry <b>60</b> of external device <b>18</b> may generate the first signal, where processing circuitry <b>60</b> is electrically coupled to communication circuitry <b>62</b> configured for wireless communication according to a first protocol and a second protocol. In some examples, external device <b>18</b> is configured to generate the first signal based on a signal program <b>66</b> stored in memory <b>64</b> of external device <b>18</b>. In some examples the first signal generated by processing circuitry <b>60</b> includes a plurality of primary portions defining a first frequency value and a first duration and a plurality of secondary portions defining a second frequency value and a second duration. Processing circuitry <b>60</b> is configured to interleave the plurality of primary portions and the plurality of secondary portions such that one primary portion occurs between two consecutive secondary portions and one secondary portion occurs between two consecutive primary portions. However, the first and last frequency portions of the first signal, whether they are primary portions or secondary portions, are bounded by one frequency portion. In some examples, the first frequency value is about 200 kilohertz (kHz), the second frequency value is about 150 kHz, and the first duration and the second duration are each about 80 microseconds (μs). However, these values are not meant to be limiting. The first frequency value, the second frequency value, the first duration, and the second duration may include any value or range of values. As such, external device <b>18</b> is configured to generate the first signal which is defined by an electromagnetic waveform which alternates between two frequency values.
0102After generating the first signal, external device <b>18</b> is configured to transmit the first signal to IMD <b>16</b> (<b>504</b>). In some examples, external device <b>18</b> transmits the first signal according to the first protocol, which is included in communication protocols <b>68</b> stored in memory <b>64</b>. In some examples, the first protocol includes any communication protocol which uses magnetic induction communication, RF communication, or tissue conductance communication. IMD <b>16</b> receives the first signal (<b>506</b>). Even though, in some examples, IMD <b>16</b> is not configured for the first protocol associated with the first signal, IMD <b>16</b> may be configured to detect the first signal by detecting electromagnetic field variations. Signal reception circuitry <b>37</b> of IMD <b>16</b> may include circuitry capable of sensing such electromagnetic field variations caused by the first signal. Additionally, processing circuitry <b>30</b> of IMD <b>16</b> is configured to identify one or more parameters of the first signal based on the electromagnetic field variations sensed by signal reception circuitry <b>37</b>. By comparing the one or more parameters of the first signal with one or more known parameters stored in memory <b>40</b> of IMD <b>16</b>, processing circuitry is 30 configured to verify that the first signal was transmitted by a trusted device (e.g., external device <b>18</b>).
0103In response to receiving the first signal and verifying that the first signal originated from external device <b>18</b>, IMD <b>16</b> is configured to transmit a set of advertisements (<b>508</b>) via a second signal. In some examples, IMD <b>16</b> is configured to transmit the second signal including the set of advertisements according to the second protocol which is stored as part of communication protocols <b>42</b> in memory <b>40</b>. The second protocol may include a Bluetooth® protocol such as a BTLE protocol having a reduced power mode and a normal power mode. In some examples, IMD <b>16</b> is configured to transmit the second signal according to the second protocol when IMD <b>16</b> is operating in the normal power mode. In other examples, IMD <b>16</b> is configured to transmit the second signal according to the second protocol when IMD <b>16</b> is operating in the reduced power mode. In some examples, prior to transmitting the set of advertisements via the second signal, IMD <b>16</b> transmits advertisements at a first advertisement rate. Additionally, IMD <b>16</b> may transmit the set of advertisements via the second signal at a second advertisement rate, where the second advertisement rate is greater than the first advertisement rate. In this way, receiving the first signal may cause IMD <b>16</b> to increase a rate in which IMD <b>16</b> transmits advertisements. However, in other examples, IMD <b>16</b> does not transmit any advertisements before receiving the first signal and IMD <b>16</b> initiates the transmission of advertisements after receiving the first signal.
0104External devices <b>18</b>, <b>20</b> are configured to receive at least one of the set of advertisements (<b>510</b>), in some cases according to the second protocol stored in memory <b>64</b>. In response to receiving the set of advertisements, any combination of external devices <b>18</b>, <b>20</b> are configured to generate a first set of random data (<b>512</b>) and transmit the first set of random data (<b>514</b>) to IMD <b>16</b> according to, in some examples, the second protocol. In examples where external device <b>20</b> generates the first set of random data, external device <b>18</b> may relay the first set of random data from external device <b>20</b> to IMD <b>16</b>. In some examples, external device <b>18</b> transmits the first set of random data to IMD <b>16</b> according to the second protocol while external device <b>18</b> is operating in the reduced power mode. In other examples, external device <b>18</b> transmits the first set of random data to IMD <b>16</b> according to the second protocol while external device <b>18</b> is operating in the normal power mode.
0105After IMD <b>16</b> receives the first set of random data (<b>516</b>), IMD <b>16</b> generates a second set of random data (<b>518</b>). In one example, the first set of random data and the second set of random data are both 64-bit integers. Subsequently, IMD <b>16</b> is configured to transmit the second set of random data, a challenge, and a first encryption key (<b>520</b>) to external devices <b>18</b>, <b>20</b> according to the second protocol. In some examples, IMD <b>16</b> is configured to transmit the second set of random data, the challenge, and the first encryption key to external devices <b>18</b>, <b>20</b> according to the second protocol when IMD <b>16</b> is operating in the reduced power mode. For example, while operating in the reduced power mode, IMD <b>16</b> may transmit the second set of random data, the challenge, and the first encryption key such that the transmission has a maximum signal strength of 150 nW, thus limiting the range of the transmission to 1 meter. In some examples, the challenge is a 64-bit random integer and the first encryption key is a 113-byte “device” key. In some examples, an encrypted version of the first encryption key and a non-encrypted version of the first encryption key are both stored as part of encryption keys <b>46</b> in memory <b>40</b> of IMD <b>16</b>. The encrypted form of the first encryption key may, in some examples, be encrypted using the Elliptic Curve Integrated Encryption Scheme (ECIES). In some examples, to prevent the first encryption key from being intercepted or otherwise compromised, IMD <b>16</b> transmits the encrypted version of the first encryption key to external devices <b>18</b>, <b>20</b>.
0106Based on the first set of random data, the second set of random data, and the non-encrypted version of the first encryption key, IMD <b>16</b> is configured to calculate a second encryption key (<b>522</b>). The second encryption key may, in some examples, define a “session” key.
0107External devices <b>18</b>, <b>20</b> receive the second set of random data, the challenge, and the encrypted version of the first encryption key (<b>524</b>) from IMD <b>16</b>. In some examples, external device <b>18</b> receives the second set of random data, the challenge, and the encrypted version of the first encryption key and relays the second set of random data, the challenge, and the encrypted version of the first encryption key to external device <b>20</b>. In other examples, external device <b>18</b> receives the second set of random data, the challenge, and the encrypted version of the first encryption key and does not transmit the second set of random data, the challenge, and the encrypted version of the first encryption key to external device <b>20</b>. In other examples, external device <b>20</b> directly receives the second set of random data, the challenge, and the encrypted version of the first encryption key from IMD <b>16</b>, thus bypassing external device <b>18</b>.
0108Any combination of external devices <b>18</b>, <b>20</b> decrypt the first encryption key (<b>526</b>) to obtain the non-encrypted version of the first encryption key using, in some examples, an ECIES private key. After external devices <b>18</b>, <b>20</b> decrypt the first encryption key, any combination of external devices <b>18</b>, <b>20</b> calculate the second encryption key (<b>528</b>) based on the first set of random data, the second set of random data, and the non-encrypted version of the first encryption key. As such, each of IMD <b>16</b>, external device <b>18</b>, and external device <b>20</b> are configured to independently calculate the second encryption key based on the same pieces of data. Such methods of independently calculating the second encryption key may be beneficial since the second encryption key does not need to be exchanged between any of IMD <b>16</b>, external device <b>18</b>, and external device <b>20</b>, thus decreasing a possibility that the second encryption key will become compromised.
0109As discussed above, IMD <b>16</b> is configured to transmit a 64-bit challenge external devices <b>18</b>, <b>20</b>. The challenge is, in some cases, not encrypted when it is transmitted from IMD <b>16</b> to external devices <b>18</b>, <b>20</b>. External device <b>18</b>, external device <b>20</b>, or any combination thereof are configured to encrypt the challenge (<b>530</b>) using the second encryption key and transmit the challenge (<b>532</b>) back to IMD <b>16</b> in encrypted form. External devices <b>18</b>, <b>20</b> may transmit the challenge to IMD <b>16</b> according to the second protocol. In some examples, external device <b>18</b> transmits the challenge to IMD <b>16</b> according to the second protocol while external device <b>18</b> is operating in the normal power mode. In other examples, external device <b>18</b> transmits the challenge to IMD <b>16</b> according to the second protocol while external device <b>18</b> is operating in the reduced power mode. IMD <b>16</b> receives the challenge (<b>534</b>) and decrypts the challenge (<b>536</b>) using the second encryption key. After decrypting the challenge, IMD <b>16</b> verifies the challenge (<b>538</b>) by cross-referencing the decrypted challenge with the challenge originally transmitted to external devices <b>18</b>, <b>20</b>. IMD <b>16</b> proceeds to transmit a verification signal and establish a secure link with external devices <b>18</b>, <b>20</b> (<b>540</b>). In some examples, IMD <b>16</b> transmits the verification according to the second protocol while IMD <b>16</b> is operating in the normal power mode. In other examples, IMD <b>16</b> transmits the verification according to the second protocol while IMD <b>16</b> is operating in the reduced power mode. External devices <b>18</b>, <b>20</b> receive the verification signal and establish the secure link with IMD <b>16</b> (<b>542</b>). In some examples, external device <b>18</b> generates the session key and relays data between IMD <b>16</b> and external device <b>20</b>, thus acting as an intermediary device. In other examples, external device <b>20</b> generates the “session” key (e.g., the second encryption key), enabling external device <b>20</b> to enter the secure link established by external device <b>18</b> and indirectly exchange data with IMD <b>16</b>. In some examples, external device <b>20</b> transmits a session key to external device <b>18</b>, allowing external device <b>18</b> to communicate independently with IMD <b>16</b>.
0110In some examples, while communicating over the secure link, any combination of IMD <b>16</b>, external device <b>18</b>, and external device <b>20</b> exchange data according to the second protocol, where IMD <b>16</b>, external device <b>18</b>, and external device <b>20</b> are operating in the normal power mode of the second protocol. In some examples, a power magnitude of signals transmitted by a device operating in the normal power mode is one hundred times greater than signals transmitted by the device operating in the reduced power mode.
0111Any one or more of IMD <b>16</b>, external device <b>18</b>, and external device <b>20</b> are configured to, at any time, issue an instruction to terminate the secure link. For example, IMD <b>16</b> may issue an instruction to invalidate encryption keys corresponding to the secure link. Additionally, IMD <b>16</b>, external device <b>18</b>, or external device <b>20</b> may set a time window associated with encryption keys corresponding to the secure link. If the time window reaches a predetermined expiration time, the secure link may be terminated.
0112The techniques described in this disclosure may be implemented, at least in part, in hardware, software, firmware, or any combination thereof. For example, various aspects of the techniques may be implemented within one or more microprocessors, DSPs, ASICs, FPGAs, or any other equivalent integrated or discrete logic QRS circuitry, as well as any combinations of such components, embodied in external devices, such as physician or patient programmers, stimulators, or other devices. The terms “processor” and “processing circuitry” may generally refer to any of the foregoing logic circuitry, alone or in combination with other logic circuitry, or any other equivalent circuitry, and alone or in combination with other digital or analog circuitry.
0113For aspects implemented in software, at least some of the functionality ascribed to the systems and devices described in this disclosure may be embodied as instructions on a computer-readable storage medium such as RAM, DRAM, SRAM, magnetic discs, optical discs, flash memories, or forms of EPROM or EEPROM. The instructions may be executed to support one or more aspects of the functionality described in this disclosure.
0114In addition, in some aspects, the functionality described herein may be provided within dedicated hardware and/or software modules. Depiction of different features as modules or units is intended to highlight different functional aspects and does not necessarily imply that such modules or units must be realized by separate hardware or software components. Rather, functionality associated with one or more modules or units may be performed by separate hardware or software components, or integrated within common or separate hardware or software components. Also, the techniques could be fully implemented in one or more circuits or logic elements. The techniques of this disclosure may be implemented in a wide variety of devices or apparatuses, including an IMD, an external programmer, a combination of an IMD and external programmer, an integrated circuit (IC) or a set of ICs, and/or discrete electrical circuitry, residing in an IMD and/or external programmer.
Contents5
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2022240107A1 | Cited by | United States of America | Search report |
| US12593198B2 | Cited by | United States of America | Search report |
| US12096247B2 | Cited by | United States of America | Search report |
| US12088634B2 | Cited by | United States of America | Applicant |
| US2023276212A1 | Cited by | United States of America | Search report |
| US10129733B2 | Cites | United States of America | Search report |
| US10158968B2 | Cites | United States of America | Search report |
| US10307599B2 | Cites | United States of America | Search report |
| US10320569B1 | Cites | United States of America | Search report |
| US10486646B2 | Cites | United States of America | Search report |
| US10499238B2 | Cites | United States of America | Search report |
| US10561849B2 | Cites | United States of America | Search report |
| US10569092B2 | Cites | United States of America | Search report |
| US10759389B2 | Cites | United States of America | Search report |
| US10880826B2 | Cites | United States of America | Search report |
| US11019195B2 | Cites | United States of America | Search report |
| US2004220631A1 | Cites | United States of America | Applicant |
| US2005204134A1 | Cites | United States of America | Applicant |
| US2006116592A1 | Cites | United States of America | Applicant |
| US2006269066A1 | Cites | United States of America | Search report |
| US2008021524A1 | Cites | United States of America | Applicant |
| US2008044014A1 | Cites | United States of America | Applicant |
| US2008044025A1 | Cites | United States of America | Applicant |
| US2008071328A1 | Cites | United States of America | Applicant |
| US2009287922A1 | Cites | United States of America | Search report |
| US2011172741A1 | Cites | United States of America | Search report |
| US2011184491A1 | Cites | United States of America | Applicant |
| US2011245700A1 | Cites | United States of America | Applicant |
| US2012271380A1 | Cites | United States of America | Search report |
| US2013108046A1 | Cites | United States of America | Applicant |
| US2013197613A1 | Cites | United States of America | Search report |
| US2014077929A1 | Cites | United States of America | Search report |
| US2014120841A1 | Cites | United States of America | Search report |
| US2014189828A1 | Cites | United States of America | Search report |
| US2014214104A1 | Cites | United States of America | Search report |
| US2014273824A1 | Cites | United States of America | Search report |
| US2015038080A1 | Cites | United States of America | Search report |
| US2015065047A1 | Cites | United States of America | Search report |
| US2015117645A1 | Cites | United States of America | Search report |
| US2015156749A1 | Cites | United States of America | Search report |
| US2015341785A1 | Cites | United States of America | Search report |
| US2016114168A1 | Cites | United States of America | Applicant |
| US2016210189A1 | Cites | United States of America | Search report |
| US2016330573A1 | Cites | United States of America | Search report |
| US2016371961A1 | Cites | United States of America | Search report |
| US2016371967A1 | Cites | United States of America | Search report |
| US2016374124A1 | Cites | United States of America | Search report |
| US2017026777A1 | Cites | United States of America | Search report |
| US2017134889A1 | Cites | United States of America | Search report |
| US2017216611A1 | Cites | United States of America | Search report |
| US2017312530A1 | Cites | United States of America | Search report |
| US2018028827A1 | Cites | United States of America | Search report |
| US2018028828A1 | Cites | United States of America | Applicant |
| US2018043173A1 | Cites | United States of America | Search report |
| US2018063784A1 | Cites | United States of America | Search report |
| US2018070222A1 | Cites | United States of America | Search report |
| US2018085592A1 | Cites | United States of America | Search report |
| US2018109946A1 | Cites | United States of America | Search report |
| US2018117346A1 | Cites | United States of America | Search report |
| US2018200525A1 | Cites | United States of America | Search report |
| US2019036886A1 | Cites | United States of America | Search report |
| US2019053031A1 | Cites | United States of America | Search report |
| US2019135229A1 | Cites | United States of America | Search report |
| US2019282819A1 | Cites | United States of America | Search report |
| US2020062217A1 | Cites | United States of America | Search report |
| US2020099526A1 | Cites | United States of America | Search report |
| US2020106877A1 | Cites | United States of America | Search report |
| US2020121937A1 | Cites | United States of America | Search report |
| US2020147401A1 | Cites | United States of America | Search report |
| US2021006652A1 | Cites | United States of America | Search report |
| US2021258418A1 | Cites | United States of America | Search report |
| US5792065A | Cites | United States of America | Applicant |
| US6993393B2 | Cites | United States of America | Applicant |
| US7013178B2 | Cites | United States of America | Applicant |
| US7127300B2 | Cites | United States of America | Applicant |
| US7155290B2 | Cites | United States of America | Applicant |
| US7668596B2 | Cites | United States of America | Applicant |
| US7725172B2 | Cites | United States of America | Applicant |
| US7844341B2 | Cites | United States of America | Applicant |
| US7978062B2 | Cites | United States of America | Applicant |
| US8102999B2 | Cites | United States of America | Applicant |
| US8326424B2 | Cites | United States of America | Applicant |
| US8649757B2 | Cites | United States of America | Search report |
| US8886296B2 | Cites | United States of America | Applicant |
| US8907782B2 | Cites | United States of America | Applicant |
| US8914106B2 | Cites | United States of America | Applicant |
| US8942795B2 | Cites | United States of America | Applicant |
| US8995949B2 | Cites | United States of America | Search report |
| US9277534B2 | Cites | United States of America | Search report |
| US9597525B2 | Cites | United States of America | Applicant |
| US9635536B2 | Cites | United States of America | Search report |
| US9687658B2 | Cites | United States of America | Search report |
| US9833628B2 | Cites | United States of America | Search report |
| US9854425B2 | Cites | United States of America | Search report |
| US9855433B2 | Cites | United States of America | Search report |
| US9889305B1 | Cites | United States of America | Search report |
| US9907486B2 | Cites | United States of America | Search report |
| US9913989B2 | Cites | United States of America | Search report |
| US20040220631A1 | Cites | United States of America | Applicant |
| US20050204134A1 | Cites | United States of America | Applicant |
8 members in 4 offices; this record represents the family
Members8
| Document | Office | Kind | |
|---|---|---|---|
| US2020252436A1 | United States of America | A1 | |
| WO2020160243A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN113396599A | China | A | |
| EP3918824A1 | European Patent Office (EPO) | A1 | |
| US11522919B2This record | United States of America | B2 | |
| US2023104064A1 | United States of America | A1 | |
| US12088634B2 | United States of America | B2 | |
| CN113396599B | China | B |
84 transactions on the USPTO file
Allowed after 2 non-final rejections, 1 final rejection and 1 RCE.
- Non-final rejections
- 2
- Final rejections
- 1
- RCEs
- 1
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Response to Reasons for AllowanceREAS | REAS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Examiner Interview Summary (PTOL - 413)MEXIN | MEXIN | |
| Interview Summary - Applicant Initiated - TelephonicEXAT | EXAT | |
| Interview Summary RecordEXIN | EXIN | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| After Final Consideration Program Additional Consideration and/or updated searchAFAC | AFAC | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| PILOT- Request for After Final Consideration ProgramRAFC | RAFC | |
| Response after Final ActionA.NE | A.NE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Examiner Interview Summary (PTOL - 413)MEXIN | MEXIN | |
| Interview Summary - Applicant Initiated - TelephonicEXAT | EXAT | |
| Interview Summary RecordEXIN | EXIN | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Email NotificationEML_NTR | EML_NTR | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Oath or Declaration Filed (Including Supplemental)C602 | C602 | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Email NotificationEML_NTR | EML_NTR | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| Application Is Now CompleteCOMP | COMP | |
| Application Is Now CompleteCOMP | COMP | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Sent to Classification ContractorPGPC | PGPC | |
| FITF set to YES - revise initial settingFTFS | FTFS | |
| Cleared by L&R (LARS)L128 | L128 | |
| Referred to Level 2 (LARS) by OIPE CSRL198 | L198 | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Patent Term Adjustment - Ready for ExaminationPTA.RFE | PTA.RFE | |
| PTO/SB/69-Authorize EPO Access to Search ResultsSREXR141 | SREXR141 | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
14 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Information on status: patent application and granting procedure in generalPUBLICATIONS -- ISSUE FEE PAYMENT VERIFIEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONSSTPP | STPP | |
| Information on status: patent application and granting procedure in generalRESPONSE TO NON-FINAL OFFICE ACTION ENTERED AND FORWARDED TO EXAMINERSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNON FINAL ACTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalDOCKETED NEW CASE - READY FOR EXAMINATIONSTPP | STPP | |
| Information on status: patent application and granting procedure in generalRESPONSE AFTER FINAL ACTION FORWARDED TO EXAMINERSTPP | STPP | |
| Information on status: patent application and granting procedure in generalFINAL REJECTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalRESPONSE TO NON-FINAL OFFICE ACTION ENTERED AND FORWARDED TO EXAMINERSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNON FINAL ACTION MAILEDSTPP | STPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Fee payment procedureENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: BIG.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP |
Numbers
- Publication
- 11522919
- Application
- 16263752
Titles
- English
- Establishing a secure communication link
Patent term adjustment
- A delay
- +378 daysthe office missed an examination deadline
- B delay
- +145 dayspendency past three years
- Applicant delay
- −31 days
- Net adjustment
- 492 days
Classification
- CPC, 14
- H04L63/205
- A61B5/0031
- H04L9/0631
- H04L63/18
- H04L63/0442
- A61B5/6869
- H04L63/105
- A61B5/686
- H04W12/50
- H04W12/04
- H04W12/63
- H04W52/0229
- H04W12/33
- A61N1/37252
- IPC, 6
- H04L9 40
- H04L9 06
- H04W12 04
- H04W52 02
- A61N1 372
- H04W12 63